CVE-2021-33224: Malicious File Upload
File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict Umbraco Forms upload endpoints and any related file upload functionality to authenticated users only, to prevent unauthenticated exploitation (crafted web.config/asp).
- Operational
Scan Umbraco site directories for any uploaded or dropped web.config/ASP webshell artifacts created via the crafted web.config and asp technique, and remove any malicious files found.
Event History
Frequently Asked Questions
What is the severity of CVE-2021-33224?
The severity of CVE-2021-33224 is critical with a score of 9.8.
How does the vulnerability in Umbraco Forms v.8.7.0 affect the software?
The vulnerability affects Umbraco Forms v.8.7.0.
What is the vulnerability in Umbraco Forms v.8.7.0?
The vulnerability in Umbraco Forms v.8.7.0 is a file upload vulnerability that allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file.
How can unauthenticated attackers exploit CVE-2021-33224?
Unauthenticated attackers can exploit CVE-2021-33224 by uploading a crafted web.config and asp file.
Are there any references available for CVE-2021-33224?
Yes, there are references available for CVE-2021-33224. You can find them at http://umbraco.com and https://our.umbraco.com/packages/developer-tools/umbraco-forms.